redact-secret · Report
Prefix-less 32-8-8 hex key triplet
Dash-segmented 32-8-8 lowercase hex triplet that both pinned tools match and three sources describe as the newer private API key; recognized only beside a same-line mailgun keyword.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^[0-9a-f]{32}-[0-9a-f]{8}-[0-9a-f]{8}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (Mailgun key objects with an 8-8 hex id): Mailgun's Keys API documents keys as objects with a separate id (shown 8-8 hex) and states no secret shape. Context twins keep the triplet byte-for-byte and rename the Mailgun key to a Mailgun identifier name (key id, domain, message id), or move the Mailgun keyword off the line
- documentation.mailgun.com/docs/mailgun/api-reference/send/mailgun/keys/post-v1-keysprovider-documentation · last read 2026-09-24 · latest outcome read · supports Mailgun's Keys API documents keys as objects with a separate id (shown 8-8 hex) and states no secret shape. Context twins keep the triplet byte-for-byte and rename the Mailgun key to a Mailgun identifier name (key id, domain, message id), or move the Mailgun keyword off the line
Tool corroborated ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/mailgun/mailgun.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports trufflehog 3.97.4: mailgun/mailgun
Tool corroborated ·
field-shape· current · observed 2026-09-24shape: 32 lowercase hex, -, 8 lowercase hex, -, 8 lowercase hex
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports mailgun-signing-key
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/mailgun/mailgun.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports Hex MailGun Token
Unresolved ·
field-role· current · observed 2026-09-24role: the newer private API key (not only a legacy signing key) (No issued key observed; recorded uncertainty (redact-secret#701).)
- github.com/mailgun/mailgun-go/issues/72third-party-writeup · last read 2026-09-24 · latest outcome read · supports Mailgun-repository contributor, 2019
- github.com/trufflesecurity/trufflehog/issues/3870third-party-writeup · last read 2026-09-29 · latest outcome read · supports 2025
- meta.discourse.org/t/current-mailgun-api-key-does-not-work/93661third-party-writeup · last read 2026-09-24 · latest outcome read · supports customer report, 2018
- meta.discourse.org/t/mailgun-secret-api-key-rejected/61852third-party-writeup · last read 2026-09-24 · latest outcome read · supports role: the newer private API key (not only a legacy signing key)
Tool corroborated ·
field-context· current · observed 2026-09-24context: same-line mailgun keyword
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports context: same-line mailgun keyword
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/mailgun/mailgun.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports context: same-line mailgun keyword
Provider documented ·
field-key-id· current · observed 2026-09-24key id: Mailgun key objects carry a separate 8-8 hex id
- documentation.mailgun.com/docs/mailgun/api-reference/send/mailgun/keys/post-v1-keysprovider-documentation · last read 2026-09-24 · latest outcome read · supports key id: Mailgun key objects carry a separate 8-8 hex id
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 5 references without stating which property each supports.
- github.com/mailgun/mailgun-go/issues/72third-party-writeup · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/582issue-or-discussion · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5800612791
- github.com/trufflesecurity/trufflehog/issues/3870third-party-writeup · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- meta.discourse.org/t/current-mailgun-api-key-does-not-work/93661third-party-writeup · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- meta.discourse.org/t/mailgun-secret-api-key-rejected/61852third-party-writeup · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Unresolved ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 1 source; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/confirm-only.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- github.com/trufflesecurity/trufflehog/issues/3870third-party-writeup · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- dash-separated lowercase hex groups of 32, 8 and 8 characters, without a prefix. The taxonomy id says "legacy signing key", but three sources describe it as the newer private API key: a Mailgun-repo contributor (2019), customer reports (2018) and a trufflehog issue (2025). Both pinned peers match the shape. No issued key has been observed.
- Basis
- T2 by scanner rules; no provider text. This family carries no frontmatter
sourcesbecause the rule links reviewed are version tags, not permalinks. - Contract in core
- #701 made the product's
mailgun_api_keydetector also report this shape, inside the shared detector; see detector-families.md. The #1012 confirm-only pass records it OWNED-ELSEWHERE (mailgun-api-key, typemailgun_api_key): medium whenmailgunappears on the same line, high under a Mailgun-named key. No new contract is proposed.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Open caveat
- No provider source shows the 32-8-8 shape and its role is unresolved (current private API key or superseded signing key); two scanner rules and three prose sources describe it. Needs one issued key.
Looks like it, but isn't
- Collisions
- an unrelated 32-8-8 hex value is not a credential; the shape is recognized only beside a
mailgunkeyword.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | mailgun-signing-key | mailgun keyword + 32-8-8 hex triplet |
| trufflehog · rules 3.97.4 | mailgun | key- + 32 characters, or a 32-8-8 hex triplet |
No rule maps to this family in flare-redact, openredaction.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- github.com/gitleaks/gitleaks/blob/v8.30.1/config/gitleaks.toml
- github.com/trufflesecurity/trufflehog/issues/3870
Research log
- redact-secret/redact-secret#582Research issue
- redact-secret/redact-secret#701Research issue
- redact-secret/redact-secret-benchmarks#259Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/confirm-only.md